#34191 [Opn->Asn]: ob_gzhandler does not enforce trailing NUL
| From: | sniper@php.net | Date: | Wed, 24 Aug 2005 14:29:00 +0000 |
| Subject: | #34191 [Opn->Asn]: ob_gzhandler does not enforce trailing NUL | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-83947@lists.php.net to get a copy of this message | ||
ID: 34191
Updated by: sniper@php.net
Reported By: mike@php.net
-Status: Open
+Status: Assigned
Bug Type: Zlib Related
PHP Version: 5CVS-2005-08-24 (CVS)
-Assigned To:
+Assigned To: iliaa
New Comment:
Ilia, it didn't quite do it..
Previous Comments:
------------------------------------------------------------------------
[2005-08-24 14:43:18] sniper@php.net
==9165== Conditional jump or move depends on uninitialised value(s)
==9165== at 0x8139541: _zval_dtor_func (zend_variables.c:35)
==9165== by 0x812EAF1: _zval_dtor (zend_variables.h:35)
==9165== by 0x812ECA4: _zval_ptr_dtor (zend_execute_API.c:386)
==9165== by 0x810A41C: php_end_ob_buffer (output.c:309)
------------------------------------------------------------------------
[2005-08-24 12:37:01] mike@php.net
Sorry, this bug is not entirely fixed.
Reproducing Script:
Similar to the previous one, but with an additional ob_end_clean()
<?php
function f()
{
$data = ob_get_contents();
while(@ob_end_clean());
ob_start('ob_gzhandler');
$step = strlen($data)/2;
echo substr($data, 0, $step);
ob_flush();
echo substr($data, $step);
}
register_shutdown_function('f');
while(@ob_end_clean());
ob_start();
echo '<pre>';
readfile(__FILE__);
?>
------------------------------------------------------------------------
[2005-08-21 18:05:34] iliaa@php.net
This bug has been fixed in CVS.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
Thank you for the report, and for helping us make PHP better.
------------------------------------------------------------------------
[2005-08-19 14:38:04] mike@php.net
Reproducing script:
<?php
function f()
{
$data = ob_get_contents();
while(@ob_end_clean());
ob_start('ob_gzhandler');
$step = strlen($data)/2;
echo substr($data, 0, $step);
ob_flush();
echo substr($data, $step);
}
register_shutdown_function('f');
ob_start();
echo '<pre>';
readfile(__FILE__);
?>
------------------------------------------------------------------------
[2005-08-19 13:41:44] mike@php.net
Description:
------------
ob_gzhandler does not always append a trailing NUL byte to the deflated
string, resulting in warnings in debug mode.
PATCH:
http://dev.iworks.at/PATCHES/ob_gzhandler_trailing_NUL.txt
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=34191&edit=1